US2009288104A1PendingUtilityA1

Extensibility framework of a network element

Assignee: ROHATI SYSTEMS INCPriority: May 19, 2008Filed: May 19, 2008Published: Nov 19, 2009
Est. expiryMay 19, 2028(~1.8 yrs left)· nominal 20-yr term from priority
H04L 69/22H04L 67/02H04L 67/564H04L 63/10H04L 67/561
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques for providing extensibility framework for processing network packets are described herein. In one embodiment, in response to a packet received at a network element, the packet is processed using a generic process for performing a first type of operations required by the packet, wherein the first type of operations is common to a type of the packet. An extended process is invoked, via an extensibility application programming interface (API), to perform a custom operation that is not common to the generic process and is not statically known to the generic process, in order to determine whether the packet is eligible to access a resource of at least one of a plurality of application servers of a datacenter, including a layer-7 access control process. The network element operates as an application service gateway for the datacenter. Other methods and apparatuses are also described.

Claims

exact text as granted — not AI-modified
1 . A method performed by a network element, the method comprising:
 in response to a packet received at the network element, processing the packet using a generic process for performing a first type of operations required by the packet, the first type of operations being common to a type of the packet; and   invoking, via an extensibility application programming interface (API), an extended process to perform a custom operation that is not common to the generic process and is not statically known to the generic process, in order to determine whether the packet is eligible to access a resource of at least one of a plurality of application servers of a datacenter, including a layer-7 access control process, wherein the network element operates as an application service gateway for the datacenter, and wherein in order to access a resource of the datacenter, each client has to go through the network element and authenticated and/or authorized by the network element.   
   
   
       2 . The method of  claim 1 , further comprising:
 performing a service lookup operation to determine types of operations to be performed on the packet; and   selecting the generic process from a plurality of generic processes statically configured to perform well-known operations associated with types of the plurality of generic processes respectively.   
   
   
       3 . The method of  claim 1 , wherein the generic process is a native proxy configured to handle well-known operations of a protocol while the extended process is an extended proxy configured to handle extended operations that are not common to the well-known operations, including rewriting a payload of a response associated with the packet. 
   
   
       4 . The method of  claim 3 , wherein rewriting the payload comprises rewriting a payload of HTTP response packets based on information extracted from corresponding HTTP request packets. 
   
   
       5 . The method of  claim 1 , wherein the generic process is part of a TCP proxy configured to initiate a standard TCP/IP protocol and wherein the extended proxy is part of a custom proxy configured to personalize the standard TCP/IP protocol. 
   
   
       6 . The method of  claim 1 , wherein the generic process is part of a policy proxy and wherein the extended process is configured to provide extended policy related services, including communicating with a remote facility for handling dynamic attributes that are used as part of application attributes used by the layer-7 access control process. 
   
   
       7 . The method of  claim 1 , wherein the extended proxy is written using Lua programming language. 
   
   
       8 . A machine-readable storage medium having instructions stored therein, which when executed by a processing logic, cause the processing logic to perform a method, the method comprising:
 in response to a packet received at the network element, processing the packet using a generic process for performing a first type of operations required by the packet, the first type of operations being common to a type of the packet; and   invoking, via an extensibility application programming interface (API), an extended process to perform a custom operation that is not common to the generic process and is not statically known to the generic process, in order to determine whether the packet is eligible to access a resource of at least one of a plurality of application servers of a datacenter, including a layer-7 access control process, wherein the network element operates as an application service gateway for the datacenter, and wherein in order to access a resource of the datacenter, each client has to go through the network element and authenticated and/or authorized by the network element.   
   
   
       9 . The machine-readable storage medium of  claim 8 , wherein the method further comprises:
 performing a service lookup operation to determine types of operations to be performed on the packet; and   selecting the generic process from a plurality of generic processes statically configured to perform well-known operations associated with types of the plurality of generic processes respectively.   
   
   
       10 . The machine-readable storage medium of  claim 8 , wherein the generic process is a native proxy configured to handle well-known operations of a protocol while the extended process is an extended proxy configured to handle extended operations that are not common to the well-known operations, including rewriting a payload of a response associated with the packet. 
   
   
       11 . The machine-readable storage medium of  claim 10 , wherein rewriting the payload comprises rewriting a payload of HTTP response packets based on information extracted from corresponding HTTP request packets. 
   
   
       12 . The machine-readable storage medium of  claim 8 , wherein the generic process is part of a TCP proxy configured to initiate a standard TCP/IP protocol and wherein the extended proxy is part of a custom proxy configured to personalize the standard TCP/IP protocol. 
   
   
       13 . The machine-readable storage medium of  claim 8 , wherein the generic process is part of a policy proxy and wherein the extended process is configured to provide extended policy related services, including communicating with a remote facility for handling dynamic attributes that are used as part of application attributes used by the layer-7 access control process. 
   
   
       14 . The machine-readable storage medium of  claim 8 , wherein the extended proxy is written using Lua programming language. 
   
   
       15 . A network element, comprising:
 a generic processing unit, in response to a packet received at the network element, for performing a first type of operations required by the packet, the first type of operations being common to a type of the packet;   a set of extensibility application programming interfaces (APIs); and   an extended processing unit capable of being invoked from generic processing unit via the extensibility APIs to perform a custom operation that is not common to the generic processing unit and is not statically known to the generic processing unit, in order to determine whether the packet is eligible to access a resource of at least one of a plurality of application servers of a datacenter, including a layer-7 access control process, wherein the network element operates as an application service gateway for the datacenter, and wherein in order to access a resource of the datacenter, each client has to go through the network element and authenticated and/or authorized by the network element.   
   
   
       16 . The network element of  claim 15 , further comprising a rule engine to determine whether the packet is eligible to access a resource of at least one of a plurality of application servers of a datacenter, including performing the layer-7 access control process. 
   
   
       17 . The network element of  claim 15 , wherein the generic process is a native proxy configured to handle well-known operations of a protocol while the extended process is an extended proxy configured to handle extended operations that are not common to the well-known operations, including rewriting a payload of a response associated with the packet. 
   
   
       18 . The network element of  claim 17 , wherein rewriting the payload comprises rewriting a payload of HTTP response packets based on information extracted from corresponding HTTP request packets. 
   
   
       19 . The network element of  claim 15 , wherein the generic process is part of a TCP proxy configured to initiate a standard TCP/IP protocol and wherein the extended proxy is part of a custom proxy configured to personalize the standard TCP/IP protocol. 
   
   
       20 . The network element of  claim 15 , wherein the generic process is part of a policy proxy and wherein the extended process is configured to provide extended policy related services, including communicating with a remote facility for handling dynamic attributes that are used as part of application attributes used by the layer-7 access control process.

Join the waitlist — get patent alerts

Track US2009288104A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.